mhoennigandClaude a4c995592f Header-only control token, masked secrets, loopback default (v0.9.9)
Finishes the small items of the security audit in
docs/prs/2026-07-08-PR#000: TODO 3, 4 and 7.

The three mutating endpoints of BuildsApiController no longer accept the
control token as a `token` query parameter — only the X-GitTally-Token
header, which the bundled UI has always used. URLs end up in access logs,
proxy logs, browser history and Referer headers, and the token never
expires, so a historical log capture would yield a valid credential.

`config:print` masks git.token as `***` on both the raw and the --full
path and names the new --show-secrets flag in a leading YAML comment, so
the output stays parseable when piped. The setup script points at
--show-secrets where it used to steer the operator to the plain token.

`server.bindAddress` now defaults to 127.0.0.1: neither the UI nor the
API authenticates read access, so reaching GitTally should require the
host's reverse proxy. Existing .gittally.yml files keep their explicit
value; the managed nginx container needs `0.0.0.0` set deliberately,
which is noted in the release notes, docs/configuration.md and
docs/deployment.md.

Released as v0.9.9, which also carries the previous two commits.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-11 07:38:33 +02:00
2026-06-09 14:31:35 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 09:07:47 +02:00
2026-06-09 11:55:23 +02:00

GitTally

Lightweight, declarative and highly opinionated software build system (CI/CD).

Documentation

Legacy Script

legacy/gitTally (bash) is deprecated and kept only as a behavioral reference for the rewrite. Do not use it for new installations; see docs/migration-from-legacy.md.

Developer Setup

Source .envrc to add tools/ to your PATH, or install direnv to have this done automatically on cd:

source .envrc

Common tasks:

./gradlew build          # compile and run all checks
./gradlew test           # run tests
./gradlew ktlintFormat   # auto-format Kotlin sources
./gradlew ktlintCheck    # check formatting (also runs as part of build)

adr-status               # show all architecture decisions at a glance

direnv

direnv sources .envrc automatically whenever you enter the repository and unloads it when you leave.

# Ubuntu
sudo apt install direnv

# add to ~/.bashrc or ~/.zshrc
eval "$(direnv hook bash)"   # or: eval "$(direnv hook zsh)"

Trust the project's .envrc once per clone:

direnv allow

Tools (tools/)

Command Description
adr-status List all Architecture Decision Records with their status and decision summary

Architecture Decision Records

Major technical decisions are documented as ADRs in docs/adrs/.

adr-status   # show all decisions at a glance

New ADRs follow the template at docs/adrs/0000-00-00.adr-template.md.

S
Description
A simple CI app mostly for GitEA and Hostsharing Managed Webserver/Webspace as well as Hostsharing Container Server.
Readme MIT
5 MiB
Languages
Kotlin 87%
HTML 4.6%
Shell 4.2%
JavaScript 3%
CSS 1.2%